AI Engine – The Chatbot, AI Framework & MCP for WordPress

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in AI Engine – The Chatbot and AI Framework for WordPress 3.3.2

    Fixed

    The AI Engine plugin for WordPress is not secure and can be exploited by hackers. This vulnerability allows attackers with certain levels of access to upload files onto the website's server and poten...

    Read More
  • Input validation vulnerability in AI Engine – The Chatbot and AI Framework for WordPress 3.3.2

    Fixed

    The AI Engine plugin for WordPress has a security issue that can be exploited by attackers who have Subscriber-level access or higher. This vulnerability allows them to make requests to any location ...

    Read More
  • Input validation vulnerability in AI Engine 3.1.8

    Fixed

    The AI Engine plugin used in WordPress has a security issue that allows for a type of attack called Server-Side Request Forgery. This can happen in any version up to version 3.1.8 through a function ...

    Read More
  • Output validation vulnerability in AI Engine 3.1.8

    Fixed

    The AI Engine plugin for WordPress has a security vulnerability that allows attackers to inject malicious code. This can only happen if the attacker has a certain level of access and if another plugi...

    Read More
  • Access violation vulnerability in AI Engine 3.1.3

    Fixed

    The AI Engine plugin for WordPress has a security issue that affects all versions up to 3.1.3. This vulnerability allows anyone to access sensitive information through the /mcp/v1/ REST API endpoint....

    Read More
  • Access violation vulnerability in AI Engine 2.9.5

    Fixed

    The AI Engine plugin for WordPress has a security issue that could allow unauthorized users to access and delete files uploaded by other users. This vulnerability affects all versions up to 2.9.5.

    Read More
  • Input validation vulnerability in AI Engine 2.9.4

    Fixed

    The AI Engine plugin for WordPress has a security flaw that allows attackers to upload any type of file onto a website using versions 2.9.3 and 2.9.4. This can only be done by someone who has access ...

    Read More
  • Access violation vulnerability in AI Engine 2.9.4

    Fixed

    The AI Engine plugin used in WordPress has a security issue where sensitive information can be exposed. This vulnerability affects all versions up to 2.9.4. The plugin's simpleTranscribeAudio feature...

    Read More
  • Input validation vulnerability in AI Engine 2.8.4

    Fixed

    A tool called "AI Engine" that works with WordPress has a security issue. This means that someone could inject harmful code into a page and it would run whenever someone opens that page. This is poss...

    Read More
  • Input validation vulnerability in AI Engine 2.8.4

    Fixed

    The AI Engine plugin for WordPress has a security issue in version 2.8.4. This is because the way it handles OAuth does not properly check for a valid redirect URL. This means that someone without pr...

    Read More
  • Access violation vulnerability in AI Engine 2.8.3

    Fixed

    The plugin called AI Engine for WordPress has a security issue that could lead to unauthorized changes or loss of data. This is because the plugin does not have a necessary check to make sure only c...

    Read More
  • Input validation vulnerability in AI Engine 2.6.3

    Fixed

    The AI Engine plugin for WordPress is at risk of being hacked through a vulnerability called SQL Injection. This is because it does not properly protect the 'value' parameter, which is a piece of inf...

    Read More
  • Input validation vulnerability in AI Engine 2.4.7

    Fixed

    The AI Engine plugin for WordPress has a security issue that allows hackers to inject malicious code through a specific parameter. This affects all versions up to and including 2.4.7. The problem is ...

    Read More
  • Input validation vulnerability in AI Engine 2.5.0

    Fixed

    The AI Engine plugin for WordPress has a security issue that could allow attackers to run their own code on a website using the plugin. This vulnerability exists in all versions of the plugin up to v...

    Read More
  • Input validation vulnerability in AI Engine 2.4.7

    Fixed

    The AI Engine plugin for WordPress has a security issue called Server-Side Request Forgery. This means that anyone who is logged in with at least subscriber-level access can make requests to other we...

    Read More
  • Input validation vulnerability in AI Engine 2.2.63

    Fixed

    The AI Engine plugin for WordPress has a security issue where anyone can upload any type of file to the site, even if they are not supposed to. This can be done by someone who has special access to t...

    Read More
  • Input validation vulnerability in AI Engine 2.1.4

    Fixed

    The AI Engine plugin for WordPress has a security issue that could be exploited by hackers. This vulnerability, present in all versions up to 2.1.4, allows attackers with editor-level access or highe...

    Read More
  • Input validation vulnerability in AI Engine 2.2.0

    Fixed

    The AI Engine plugin for WordPress, which includes features like chatbots and assistants, has a security vulnerability. This means that hackers can insert harmful code into the chat data, which will ...

    Read More
  • Input validation vulnerability in AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! 2.1.4

    Fixed

    The AI Engine plugin for WordPress, which includes features like chatbots, generators, assistants, and GPT 4, has a security vulnerability that allows for unauthorized file uploads. This means that s...

    Read More
  • Input validation vulnerability in AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! 1.9.98

    Fixed

    The AI Engine plugin for WordPress has a security issue where anyone can upload any type of file to the website without being authenticated. This could potentially allow hackers to run code on the we...

    Read More
  • Input validation vulnerability in AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable 1.6.83

    Fixed

    The AI Engine plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This type of attack allows an attacker to inject malicious code into a website that will be ex...

    Read More